Hacker News new | ask | show | jobs
by 40four 1637 days ago
What are the chances these emails were actually sent out in error, like Lastpass claims? It’s not in-plausible, but I also take it with a grain of salt.

To be fair to them, I don’t think we’ve seen any reports of folks password DBs actually being compromised. Just a lot of presumed failed attempts.

If the e-mails were sent in error, then it’s all much to do about nothing. If the master passwords were actually compromised, then the system still successfully protected the clients password assets.

2 comments

For whatever it is worth, the same day people started getting the emails someone attempted to login to both my outlook.com account and Steam account using the correct passwords and I got a 2FA alert, that has never happened before and then the next day I also got an alert from Lastpass.

Could be some crazy coincidence but what Lastpass is saying isn't adding up.

Sums up my feelings really. I genuinely think that what they're saying is probably true, that these emails were sent in error (and I have to say I don't envy their teams at all in having to deal with the fallout from this), but it's also entirely understandable that many people will have been justifiably spooked to the point where they probably won't continue to use their services now.